Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 94% confidence
- Finding
- The skill instructs the agent to execute local CLI commands, read files from the workspace, access environment-provided credentials, and make outbound network requests, yet it declares no permissions. This mismatch reduces transparency and can bypass policy or user expectations about what the skill is allowed to do, increasing the risk of unintended shell execution or secret exposure through the helper scripts.
